VulnerabilityModified
CVE-2014-2869
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to obtain sensitive information via requests to unspecified URIs, as demonstrated by pathname, SQL server, e-mail address, and IP address information.
MEDIUM 5.0EPSS 1.97%
Does this matter?
Lower severity and a low EPSS score (1.97%). Track it; it rarely justifies an emergency change on its own.
Description
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to obtain sensitive information via requests to unspecified URIs, as demonstrated by pathname, SQL server, e-mail address, and IP address information.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.97% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- paperthin/commonspot content server
- Source
- cve@mitre.org
References
- http://www.kb.cert.org/vuls/id/437385US Government Resource
- http://www.kb.cert.org/vuls/id/437385US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.